Using an app password
Outlook, Thunderbird and phone mail apps sign in with an app password instead of your MyPandos account password. Here is how to create one, use it, and revoke it.
An app password is a long, random password that belongs to one mailbox and one device. You use it in place of your MyPandos account password when you set up Outlook, Thunderbird, Apple Mail, or the Mail app on your phone.
Why mail apps need one
Webmail signs you in through your MyPandos account, with the multi-factor step that goes with it. Desktop and phone mail apps connect over the standard mail protocols — IMAP for reading and SMTP for sending — and those protocols have no way to show you that sign-in page or ask you for a second factor. An app password is what those apps use instead.
Giving each device its own app password is also safer than reusing one password everywhere. If a phone is lost or a laptop is replaced, you revoke that one password and nothing else stops working.
Create an app password
- Sign in to your MyPandos dashboard and open the service that holds your mailbox.
- Open the Email tab and find the mailbox you want to connect.
- Choose App passwords and create a new one.
- Give it a name that tells you which device it belongs to — “iPhone”, “Outlook laptop”, “front desk PC”. A name is required, and it is how you will recognise the right entry when you come to revoke it.
- Copy the password that appears.
If your mailbox includes webmail, its user settings offer the same app passwords — use whichever is closer to hand.
It is shown once
The password appears one time, at the moment you create it. Close that screen and it cannot be shown again — we do not keep a readable copy of it. Paste it into the mail app straight away. If you lose it before you use it, revoke it and create another; there is no limit on how many you create.
Use it in your mail app
Set the account up as an IMAP account. Your username is always your full email address — not just the part before the @ — and the password is the app password, not your MyPandos password.
- Incoming, IMAP (recommended): port 993, SSL/TLS
- Incoming, POP3 (only if your app offers nothing else): port 995, SSL/TLS
- Outgoing, SMTP: port 465, SSL/TLS
- Outgoing, SMTP alternative: port 587, STARTTLS
The server name to use for both incoming and outgoing is shown with these settings on the same Email tab. Use the name shown there rather than guessing one from your domain — a guessed name produces a certificate warning and the connection fails.
Outgoing mail needs to authenticate as well. If your app asks, tell it to use the same username and password as incoming.
Choose IMAP over POP3 where you can: IMAP keeps your mail on the server so every device sees the same mailbox, while POP3 downloads it and, with typical settings, removes it from the server.
Revoke one
Revoke an app password when a device is lost or stolen, when you replace or sell a phone or laptop, or when someone leaves and their device still has the mailbox on it.
- Open the Email tab, find the mailbox, and open App passwords.
- Find the entry by the name you gave it and revoke it.
That device can no longer sign in to the mailbox. Your other devices keep working, webmail is unaffected, and your MyPandos account password does not change. If you revoke the wrong one, create a new app password and enter it on that device.
Keep it safe
Treat an app password like the mailbox itself — it can read and send your mail. Do not email it, do not paste it into a chat, and do not put one app password on several devices: that removes the whole point of being able to revoke a single one.
A device left holding a revoked or outdated password will keep retrying, and repeated failed sign-ins from your location can get that location temporarily blocked — which takes webmail down with it. When you change an app password, update every device that used it.
How helpful was this article?